CVE-2026-9375

Publication date 19 June 2026

Last updated 19 August 2026


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Read the notes from the security team

Status

Package Ubuntu Release Status
python-urllib3 26.04 LTS resolute
Vulnerable, fix deferred
25.10 questing Ignored end of life, was deferred [2026-08-17]
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred
16.04 LTS xenial
Vulnerable, fix deferred
14.04 LTS trusty
Vulnerable, fix deferred
python-pip 26.04 LTS resolute
Vulnerable, fix deferred
25.10 questing Ignored end of life, was deferred [2026-08-17]
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred
16.04 LTS xenial
Vulnerable, fix deferred
14.04 LTS trusty
Vulnerable, fix deferred

Notes


mdeslaur

On focal and earlier, the python-pip package bundles python-urllib3 binaries when built. After updating python-urllib3, a no-change rebuild of python-pip is required. On jammy and later, python-urllib3 is bundled in the python-pip package and needs to be patched. While the NVD entry references the 2bdcc44d commit that fixed CVE-2026-44432, it doesn't appear that that would fix the issues described in this CVE. The commit id is probably wrong. No details about this issue or a fix for it as of 2026-08-17, marking as deferred for now.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
python-urllib3

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H


Access our resources on patching vulnerabilities